[CLSA-2026:1784901236] golang: Fix of CVE-2026-39822
Type:
security
Severity:
Low
Release date:
2026-07-24 13:54:21 UTC
Description:
- CVE-2026-39822: fix os.Root escape via trailing slashes in symlink paths where openat resolved a slash-terminated final component, allowing operations to escape the root
CVEs fixed:
Updated packages:
  • go-toolset-1.25.7-1.el9_6.tuxcare.els14.x86_64.rpm
    sha:eaf1cec4b3bec95456a0cc37fef9e2e59c90bb44d1194f761d8186d81ba6509a
  • golang-1.25.7-1.el9_6.tuxcare.els14.x86_64.rpm
    sha:3a96700fc0b5b5b15e14cb5410c34304dfdd363f62f34fbaba8955b840b867e7
  • golang-bin-1.25.7-1.el9_6.tuxcare.els14.x86_64.rpm
    sha:3f7ff1b061dc6653b2d80105502d33b0e984a331c0b1017a9a9fdf53f3344da3
  • golang-docs-1.25.7-1.el9_6.tuxcare.els14.noarch.rpm
    sha:7c50b2cfe2ecae60e238b3224a1073eb5377db975b9ce66345388a5a555e26dd
  • golang-misc-1.25.7-1.el9_6.tuxcare.els14.noarch.rpm
    sha:d4f741bb4002dfa43d5e690373eeeea3f1ee9703e0b1ac20f234f9bb35ab67ec
  • golang-race-1.25.7-1.el9_6.tuxcare.els14.x86_64.rpm
    sha:3c580fd79295b11fdafad108c95ef76b5173b9f41cd68ea50b75ac53f7d7474f
  • golang-src-1.25.7-1.el9_6.tuxcare.els14.noarch.rpm
    sha:f98d00c6fa48ae19744dc84a77bbf0d05a516fe5285e3758211b30021537932a
  • golang-tests-1.25.7-1.el9_6.tuxcare.els14.noarch.rpm
    sha:84a85388b98fe81856329c64f0aece267af836a0b89b2a0d92ad7a33c9c7b35c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.